Privacy notice

What we handle, and why.

A plain-language description of the information dishreveal uses to run restaurant workspaces, public menus, and optional dish previews.

Draft · Last reviewed September 20, 2026 · Owner and effective date: pending

Scope

This draft applies to the dishreveal marketing site, restaurant dashboard, public menus, authentication, analytics, image processing, 3D model generation, and hosted assets.

It does not replace a restaurant’s own privacy notice or explain how a restaurant handles information outside dishreveal.

Information in the current MVP

  • Restaurant accounts: name, email, verification state, login sessions, and security metadata such as IP address and browser user-agent.
  • Restaurant workspaces: restaurant identity, contact details, menu content, prices, ingredients, allergens, dietary notes, availability, images, and generated model metadata.
  • Model generation: an uploaded dish image or a public image URL, provider task identifiers, generated model URLs, thumbnails, dimensions, and processing errors.
  • Public-menu measurement: menu and dish events, source label, a temporary browser session identifier, bounded metadata, and timestamps.

How we use it

  • To authenticate restaurant users and protect their workspace.
  • To store, publish, and display restaurant menu content.
  • To generate and deliver optional 3D/AR assets when a restaurant requests them.
  • To understand aggregate menu engagement and improve the product.
  • To maintain security, prevent abuse, troubleshoot failures, and operate the service.

The final lawful basis and controller/processor roles depend on the launch jurisdictions and the contract with each restaurant. They are not finalized in this draft.

Public menus and restaurant responsibility

When a restaurant publishes a menu, its selected restaurant, menu, dish, image, and model information is intended to be public. Restaurant teams are responsible for keeping prices, availability, ingredients, allergen information, dietary labels, and visual representations accurate.

Generated 3D and AR views are approximate visual references. The ordinary dish image and written details remain the source of truth.

Service providers

The current implementation uses Neon/Postgres, Vercel, Tripo, Google Cloud Storage when configured, and browser/CDN services. Vendor regions, contractual terms, retention, and transfer mechanisms still require review before production launch.

Retention, choices, and requests

The repository has not yet enforced an approved retention schedule for accounts, sessions, analytics, source images, model jobs, provider copies, storage objects, or logs. The final notice must publish those periods and explain deletion, correction, access, and export routes.

Public menus remain usable without an account, camera permission, 3D, AR, or non-essential measurement. First-party menu analytics is disabled until a guest accepts it, and the choice can be changed from the Cookies page.

Changes and contact

This draft will receive an owner, effective date, version, legal entity, jurisdiction statement, and monitored privacy contact before it is treated as an effective notice.

For now, use the contact route for product questions. Do not send passwords, API keys, identity documents, or other sensitive material through the demo contact form.